Splunk Enterprise

Can Splunk Light be converted to a heavy forwarder?

smithpj
Explorer

Before we purchased an Enterprise license, we had an installation of Splunk Light running collecting a smallish amount of data. We've turned up an Enterprise search head, with a couple of indexers and we're just now circling back to this initial installation we had of Light. Is it possible to take it that Light installation that is still humming along, and turn it into a heavy forwarder for our new Enterprise solution or would it be best to just scrap that install, and rebuild it anew as strictly a forwarder?

jterry
Splunk Employee
Splunk Employee

As rbittner says above:

You have to convert your SL instance to an Enterprise instance. Installing SE on top of SL will work. The SE trial license will trump the SL license. Once you have your instance running as SE point it to the master license server.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

You should be able to just upgrade that instance to SPlunk Enterprise instance (and setup that as HF). It should be easy as per the Splunk Light page http://www.splunk.com/en_us/products/splunk-light.html

0 Karma

smithpj
Explorer

Sadly I get dead-ended at this page:

http://docs.splunk.com/Documentation/SplunkLight/6.3.0/Installation/AboutmigratingSplunkLight

It says that yes it's a valid migration path, but nothing more on /how/ to fulfill that migration.. I would it might be as simple as just applying a license, but Light doesn't appear to allow me to point it to a remote master license server..

0 Karma

somesoni2
SplunkTrust
SplunkTrust

You should just install Splunk Enterprise on top of your Splunk Light installation. After that you will get all the options, including remote license master configuration.

0 Karma

rbittner_splunk
Splunk Employee
Splunk Employee

You have to convert your SL instance to an Enterprise instance. Installing SE on top of SL will work. The SE trial license will trump the SL license. Once you have your instance running as SE point it to the master license server.

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...